What May My Proxy Say for Me?
Separate behavioural simulation from disclosure and authority policy.
Chapter 32 lets the proxy act. But some actions do more than change external state — they make statements, promises, and commitments others attribute to the principal. “€400 works for me” as a draft, a negotiation signal, an acceptance, and a binding commitment are four different exercises of authority wearing identical text. This chapter treats utterances as typed consequential actions:
Authority to act for me does not automatically imply authority to speak as me, make claims about me, disclose information about me, or commit me through language.
With the sharper split: SPEAK FOR ME (clearly attributed proxy representation) is not SPEAK AS ME (recipient led to believe the principal personally authored). Chapter 31’s authorship triad becomes operational machinery.
Speech acts carry their own authority prices
Proxy speech is never send_message(text). The SpeechGrant classifies communicative function — DRAFT, INFORM, ASSERT, DISCLOSE, REQUEST, OFFER, NEGOTIATE, ACCEPT, PROMISE — each with its own price, because authority attaches to function, not generation:
DRAFT / FACTUAL RELAY / REQUEST bounded authority
NEGOTIATE bounded + consequence constraints
REPRESENTATION ABOUT PRINCIPAL higher authority
PRIVATE DISCLOSURE specific disclosure authority
ACCEPT TERMS / PROMISE FUTURE ACTION explicit commitment authority
“Could you offer €380?” without “Agreed, we’ll take it.” An action can stay inside spending bounds while its pursuit-speech is strategically incompetent (“I’d happily pay €450” opening against a €450 cap) — authorised ≠ competent, surviving composition again. Negotiation language shapes the counterparty’s evolving model of what the principal wants, so Zhu et al.’s anomaly evidence (verified Ch 32) now motivates conversational-commitment constraints, not just final-state bounds. Assisted authorship (human reads exact message, human sends) and proxy speech (scope granted, wording and sending autonomous) are different authorship histories — and most AI-mediated-communication literature studies the former, a fence this chapter respects when importing its findings.
Provenance over labels, disclosure without approval-maximising
The disclosure literature is genuinely mixed, which is precisely the chapter’s point. AI-assisted trust-game writing (iScience 2025, verified: N=1,637 preregistered, similar behavioural and stated trust with less effort, disclosure without significant penalty — transactional setting) sits beside the AI-penalty finding (2026, verified: N=547 preregistered 3×2, AI involvement judged less trustworthy and authentic, with a disclosure paradox creating perverse non-disclosure incentives), the 13-experiment trust-penalty line, smart-reply results (Hohenstein et al., Sci. Rep. 2023, verified: 219 pairs, speed and sentiment gains, suspected use penalised while actual use improved affiliation), and source-disclosure messaging work (Lim & Schmälzle 2024, verified: slight evaluation bias on disclosure, rankings unmoved). The conclusion the chapter draws against the temptation:
Disclosure should not be designed to maximise recipient approval. Sometimes it costs. Hidden proxying is not thereby equivalent to disclosed proxying.
Hence provenance describing agency instead of binary AI-GENERATED: “written by the principal with drafting assistance” vs “sent by the delegated assistant without per-message review” vs “negotiated within authorised price/refund limits” — disclosing the delegation relationship relevant to authorship, authority, or commitment interpretation. The authority/disclosure 2×2 stays independent: disclosure cannot create authority, authority does not settle disclosure; a factually correct utterance can still fail on authorship, disclosure, or authority grounds.
Epistemic humility and the apology edge
Personal-model state is never disclosure authority: “probably considering changing jobs” does not authorise telling the recruiter. The chapter grades epistemic speech — KNOWN USER FACT, MODEL INFERENCE, PREDICTED OPINION, CURRENT COMMITMENT — and requires refusal where positions are manufactured: “I don’t have authority to state the principal’s view on that point” is a first-class output. Every utterance further traces two independent lineages — may I say this (SpeechGrant) and may I use this information to formulate this (DataUseAuthority) — with use/state/attribute as three distinct permissions: internal use never implies external statement, and neither implies principal attribution. Relational privacy binds speech directly: possession of another person’s message creates no authority to quote, profile, infer from, or disclose it (PrivaCI-Bench, ACL 2025 long, verified: privacy as whole social-context flow beyond PII). The deliberate stress case is apology: “I’m sorry” as reported remorse, social ritual, or manufactured emotion — exposed rather than ruled, because authorship questions of exactly this shape recur everywhere proxies speak.
EXP-33 crosses speech authority (human-approval / drafting-only / broad-task-without-speech-grant / typed SpeechGrant / grant-plus-provenance-gates) with ten speech acts including the apology edge, scoring unauthorised speech, commitment and disclosure overreach, attribution failure, inference-as-fact, strategic failure, and revocation failure — headline: can a proxy communicate usefully while recipients correctly determine whose words these are, what authority they carry, and which claims belong to the principal? Trust optimisation refused; recipient-trust headlines rejected per the context-sensitive literature. What the chapter leaves untouched is discovery before counterparties are known: speaking to someone identified is solved here; finding whom to speak with, without broadcasting private states, is Chapter 34’s problem.
A proxy can now speak under bounded authority to a known recipient. But valuable communication often begins earlier — discovering that another person holds compatible information, interests, or opportunities, without revealing everyone’s private states to find one another.
References
- AI-assisted trust games (iScience 2025, DOI 10.1016/j.isci.2025.114092). Verified: N=1,637 preregistered, similar trust + efficiency, disclosure no significant penalty. Transactional fence.
- AI penalty/disclosure paradox (2026, S2949882126000551). Verified: N=547 3×2, penalty + paradox.
- 13-experiment trust-penalty line: cited as literature direction; individual verification at Part IV pass.
- Hohenstein et al. (2023). Sci. Rep. 13:5487. DOI 10.1038/s41598-023-30938-9. Verified: 219 pairs, speed/sentiment gains, suspected-use penalty vs actual-use affiliation gain.
- Lim & Schmälzle (2024). Comp. Hum. Behav.: Art. Humans 2:100058. DOI 10.1016/j.chbah.2024.100058. Verified: slight evaluation bias, rankings unmoved.
- Zhu et al. NLLP 2025 (verified Ch 32): conversational-commitment lesson reused.
Proposed experiment EXP-33: speech authority × provenance
Status: PROPOSED. Per the design above (A–E, ten speech acts incl. apology, seven failure classes, attribution-correctness headline, trust optimisation refused). EXP-33 additionally crosses speech/data-use/disclosure authority with third-party interests — authorised speech with unauthorised evidence, negotiation with unnecessary disclosure, principal-authorised disclosure touching third-party confidences, valid SpeechGrant with expired DataUseAuthority — where the correct outcome may be reformulate without the unauthorised information rather than blanket DENY.